Record file mode in the manifest, 0000 unless asked (closes #161)
check / check (push) Failing after 8s

MFFilePath gains mode (field 304): a file's permission bits, 0777 at
most, or 0000, meaning none recorded. gen and freshen record real modes
only with --include-permissions (ScannerOptions.IncludePermissions); the
builder keeps only mode.Perm(), so setuid, setgid and sticky are never
written. list -l and export show the mode in octal. check reports
MODE_MISMATCH for a recorded mode other than 0000 the file lacks. fetch
refuses a manifest with a mode above 0777 before requesting any file,
sets each recorded mode on the files it writes, and downloads again a
present file whose mode differs. The decoding-cost bound counts a file
entry at 176 bytes, up from 160.

Model: opus-5-5
This commit is contained in:
2026-10-06 04:17:12 +00:00
parent ce66f7c1c1
commit ea044600d4
26 changed files with 605 additions and 106 deletions
+16 -11
View File
@@ -261,9 +261,12 @@ are now tracked only in the [issues](https://git.eeqj.de/sneak/mfer/issues).
- `mfer gen` / `mfer gen .`
- recurses under current directory and writes out an `index.mf`
- records every file's mode as `0000` unless given `--include-permissions`,
which records each file's permission bits (`0777` at most)
- `mfer check` / `mfer check .`
- verifies checksums of all files in manifest, displaying error and exiting
nonzero if any files are missing or corrupted
nonzero if any files are missing or corrupted, or have permission bits
other than the mode the manifest records, unless that is `0000`
- warns about each file under the base directory that the manifest does not
list, hidden files included; with `--no-extra-files` each one is a failure
instead
@@ -271,16 +274,18 @@ are now tracked only in the [issues](https://git.eeqj.de/sneak/mfer/issues).
- fetches `/stuff/index.mf` and downloads all files listed in manifest into
the current directory, or the one given with `--dest`, and assures
cryptographic integrity of downloaded files. A file already there with the
size and hash the manifest lists is skipped. Once every file is in place,
the manifest is saved there as `index.mf`, so `mfer check` can verify the
tree later. Each file is downloaded to a temp file beside it, such as
`.a.txt.tmp` for `a.txt`, then moved into place. A manifest is refused
before any file is downloaded if it lists a file where fetch writes
another: at another listed file or a directory one is in, at the temp file
of a listed file, or at `index.mf` or `.index.mf.tmp` at the top of the
tree. Names are compared in any letter case, on every filesystem, since on
a case-insensitive one `A.txt` and `a.txt` are one file; a directory two
listed files are in must be spelled alike in both.
size, hash and recorded mode the manifest lists is skipped. Once every
file is in place, the manifest is saved there as `index.mf`, so
`mfer check` can verify the tree later. Each file is downloaded to a temp
file beside it, such as `.a.txt.tmp` for `a.txt`, given the mode the
manifest records unless that is `0000`, then moved into place. A manifest
is refused before any file is downloaded if it records a mode above
`0777`, or lists a file where fetch writes another: at another listed file
or a directory one is in, at the temp file of a listed file, or at
`index.mf` or `.index.mf.tmp` at the top of the tree. Names are compared
in any letter case, on every filesystem, since on a case-insensitive one
`A.txt` and `a.txt` are one file; a directory two listed files are in must
be spelled alike in both.
- `mfer fetch --require-signature <fingerprint> https://example.com/stuff/`
- as above, but first refuses a manifest not signed by the key with that
fingerprint, as `mfer check --require-signature` does, before downloading